PT-2026-79646 · Linux · Linux Kernel
CVE-2026-74641
·
Published
2026-08-22
·
Updated
2026-08-27
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the ALSA usx2y component where the
snd us428ctls vm fault() function converts a faulting page offset into a kernel address without performing any boundary checks. Because snd us428ctls mmap() only verifies the mapping length and not the offset, and the memory management layer imposes no ceiling for character devices, a user can provide a page offset above zero to resolve a page outside the intended object. This allows a process that can open the hwdep node of an attached US-X2Y device to gain read-write access to kernel memory it does not own. If the offset points to an unpopulated vmemmap region, it results in a kernel oops. The same issue affects the pcm hwdep handler in usx2yhwdeppcm.c.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel